software-realtime
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The diagnostic scripts
scripts/check_ws_smoke.pyandscripts/ws_smoke_test.pyrepresent a potential indirect injection surface. - Ingestion points: The
--urlcommand-line argument in both scripts triggers connections to external servers. - Boundary markers: The scripts lack explicit instructions to the agent to ignore potentially malicious content in server responses.
- Capability inventory: The scripts use
socket.create_connectionand thewebsocket-clientlibrary to establish network connections. - Sanitization: Input is parsed using the standard
urllib.parselibrary. Given the purpose of these scripts is technical diagnostics and they do not execute server-returned data as code, this finding is considered safe for the intended use case. - [EXTERNAL_DOWNLOADS]: The
data/sources.jsonfile references technical documentation from well-known and trusted entities, including Mozilla (MDN), Cloudflare, Apple (WebKit), and Redis. These are legitimate informational resources. - [SAFE]: The skill's documentation and code perform standard real-time systems implementation and testing. No evidence of prompt injection, obfuscation, data exfiltration, or persistence mechanisms was found. The logic aligns with best practices for WebSocket and CRDT-based development.
Audit Metadata